CVE Tools

CVE-2026-58231

Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

Published: Aug 11, 2026Updated: Aug 17, 2026 Sources: CVE List NVDCWE-94

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

In plain language

AI Act now

CVE-2026-58231 is a critical security flaw in SAP Commerce Cloud’s Data Hub Adapter that lets an attacker take over the server over the network without logging in—this is serious and needs immediate action if you use this component.

Executive summary

CVE-2026-58231 is an improper authorization vulnerability (CWE-94) in SAP Commerce Cloud (Data Hub Adapter) where a missing authorization check in the default authentication client enables unauthenticated attackers over the network to execute arbitrary code on the server.

If affected, business impact
Full server takeoverCustomer and business data theftData tampering and fraud riskService disruption and downtime

What to do now

  1. Confirm whether your SAP Commerce Cloud deployment is running the Data Hub Adapter component.
  2. Check whether the affected “default authentication client” is enabled/used in your configuration (look for default authentication client setup in your SAP Commerce configuration).
  3. If the Data Hub Adapter is in use, treat the system as internet-reachable risk and restrict access at the network layer (allowlist only trusted IPs/VPNs; block public access).
  4. Apply any vendor-provided mitigation or emergency guidance for CVE-2026-58231 as soon as it is released; if no fixed version is available yet, implement the network restriction and compensating controls immediately.
  5. Monitor for suspicious access patterns and server-side errors consistent with exploitation attempts, and retain logs for investigation.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:CC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:CScope
Changed
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

SAP_SE
commercial·DEaka sap netweaver application server for abap, sap businessobjects business intelligence platform

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Execution
Initial Access
View detailed technique mapping

References

6

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-58231 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows